Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 78

  • Download
  • Add to my manuals
  • Print
  • Page
    / 188
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 77
ServerIron ADX Firewall Load Balancing Guide 67
53-1002436-01
Configuring active-active HA FWLB with VRRP
3
DRAFT: BROCADE CONFIDENTIAL
SI-Ext-B(config-fw-2)# sym-priority 1
SI-Ext-B(config-fw-2)# fwall-info 1 3/1 10.10.2.222 10.10.1.1
SI-Ext-B(config-fw-2)# fwall-info 2 4/1 10.10.2.222 10.10.1.2
SI-Ext-B(config-fw-2)# fwall-info 3 3/1 10.10.2.223 10.10.1.1
SI-Ext-B(config-fw-2)# fwall-info 4 4/1 10.10.2.223 10.10.1.2
SI-Ext-B(config-fw-2)# fw-predictor per-service-least-conn
SI-Ext-B(config-fw-2)# l2-fwall
SI-Ext-B(config-fw-2)# exit
SI-Ext-B(config)# vlan 1
SI-Ext-B(config-vlan-1)# static-mac-address 00e0.5201.0426 ethernet 3/1
priority 1 router-type
SI-Ext-B(config-vlan-1)# static-mac-address 00e0.5201.2180 ethernet 4/1
priority 1 router-type
SI-Ext-B(config-vlan-1)# exit
ServerIronADXA(config)# router vrrp
ServerIronADXA(config)# interface ethernet 4/12
ServerIronADXA(config-if-4/12)# ip address 10.10.6.112/24
ServerIronADXA(config-if-4/12)# ip vrrp vrid 1
ServerIronADXA(config-if-4/12-vrid-1)# backup
ServerIronADXA(config-if-4/12-vrid-1)# ip-address 10.10.6.111
ServerIronADXA(config-if-4/12-vrid-1)# activate
ServerIronADXA(config-if-4/12-vrid-1)# exit
ServerIronADXA(config-if-4/12)# exit
SI-Ext-B(config)# write memory
Usage notes
Brocade FWLB design assumes that any Network Address Translation (NAT) is performed by the
load balanced firewalls, but it is not performed by the ServerIron ADXs. Under specific conditions, it
is possible to use NAT pools and static entries on ServerIrons that are also engaged in FWLB.
Under the following conditions, you cannot configure the ServerIrons' VRRP or VRRP-E virtual IP
address as the firewalls' default gateway:
When the FWLB is configured
When the VRRP or VRRP-E is configured
When NAT is configured on the firewalls' external ServerIron ADX (for example, IP NAT is
configured globally)
When firewalls are directly connected to ServerIron ADX
If the FWLB environment meets these conditions, on the firewalls you must configure the default
gateway address to be the interface address (physical or VE) of the directly connected ServerIron
instead of the VRRP or VRRP-E Virtual IP. On the ServerIrons performing NAT, you must use floating
default routes or some other dynamic routing protocol to maintain connectivity in case either
ServerIron loses its upstream link.
Commands on internal ServerIron ADX A (SI-Int-A)
ServerIronADX> enable
ServerIronADX# configure terminal
ServerIronADX(config)# hostname SI-Int-A
SI-Int-A(config)# vlan 1
SI-Int-A(config-vlan-1)# always-active
SI-Int-A(config-vlan-1)# no spanning-tree
SI-Int-A(config-vlan-1)# router-interface ve 1
SI-Int-A(config-vlan-1)# exit
Page view 77
1 2 ... 73 74 75 76 77 78 79 80 81 82 83 ... 187 188

Comments to this Manuals

No comments